Skip to content

Commit

Permalink
Hide user guid header from client
Browse files Browse the repository at this point in the history
* X-USER-GUID can be used in nginx access logs
  Consumption in nginx conf: 'user_guid=$upstream_http_x_user_guid'

Co-authored-by: Philipp Thun <[email protected]>
  • Loading branch information
johha and philippthun committed Mar 25, 2021
1 parent 863e5fa commit ebdf749
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions jobs/cloud_controller_ng/templates/nginx.conf.erb
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ http {
access_log /var/vcap/sys/log/cloud_controller_ng/nginx-access.log main;
access_log syslog:server=127.0.0.1,severity=info,tag=vcap_nginx_access main;

proxy_hide_header X-USER-GUID; #user guid header should not be forwarded to client

sendfile on; #enable use of sendfile()
sendfile_max_chunk 1M; #make sure not to block on fast clients reading large files
tcp_nopush on;
Expand Down

0 comments on commit ebdf749

Please sign in to comment.